feat(oracle): granturi dictionar PACK_DIAG_SPATIU + sys-grants.sql legat in flux
Trei probleme gasite pregatind migrarea unui client de pe Oracle XE 11 pe XE 21c. 1. sys-grants.sql nu era rulat de niciun script PowerShell. Era referit doar din run-all-sys.sql, care se lanseaza manual. Pe orice instalare facuta cu RunAll.cmd lipseau sinonimele SYS (SYN_NEWSCHEMA, SYN_NEWSCHEMAJOB, EXECUTESCRIPTOS, SYN_PINFO), DMPDIR si granturile pe DBMS_SCHEDULER / UTL_* / DBMS_CRYPTO catre CONTAFIN_ORACLE. Legat ca STEP 3 in 04-create-synonyms-grants, dupa import - unde propriul header al fisierului spune ca trebuie rulat. 2. Granturile de dictionar cerute de PACK_DIAG_SPATIU lipseau complet. Consolidez sys_2026_08_03_05, sys_2026_08_03_07 si sys_2026_08_06_07 in sectiunea [5/5] din sys-grants.sql: SELECT direct pe 18 vederi dba_*/v$*, idempotent, cu ORA-00942 tratat pentru vederile absente pe alte editii/versiuni. Grantul prin rolul DBA nu ajunge - rolurile nu se aplica in pachetele cu drepturi de definitor, iar PACK_DIAG_SPATIU e exact asa; fara ele ramane INVALID si DIAGSPATIU_ZILNIC nu ruleaza. 3. Capcana la migrari: tabela de versiuni a lui PACK_MIGRARE traieste in CONTAFIN_ORACLE si vine cu DMP-ul, deci baza noua raporteaza scripturile sys_* drept aplicate si ROAACTUALIZARI le sare, desi in SYS nu exista nimic. De aceea obiectele si granturile SYS se pun la instalare, nu prin actualizator. Documentat in sys-updates/README.md si in ghidul nou. 07-verify-installation raporteaza nominal care dintre cele 18 granturi lipsesc. Documentatie: docs/instalare-si-migrare-oracle.md - arbore de decizie intre roa-windows-setup/ (client pe Windows), migration/ (Oracle in Docker pe LXC 108) si new-roa-oracle-server/ (arhiva). Include de ce migration/ nu se foloseste la un client Windows: creeaza PDB ROA cu OraclePass123, sinonime minimale, fara SERVER_INFO / ROAUPDATE / ACL / sqlnet.ora, iar sys_objects.sql de acolo creeaza INFO in SYSTEM - cauza cunoscuta a ORA-01653 la actualizare. Plus comenzile de export din XE 11 / 10g si plafonul XE de 12 GB. Corectat pe drum: dual-edition-test-plan si issues-se-prod indicau clonarea VM 302 -> 303 pentru testul SE, dar 303 e ocupat de Win11-Adina. Mutat pe 304. NETESTAT pe baza reala - VM 302 e oprit. Scripturile trec doar parse-check PowerShell. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SzF1hf4aFS1tmJWpPMiwGp
This commit is contained in:
@@ -1,5 +1,10 @@
|
||||
# ROA Oracle Database Setup for Windows
|
||||
|
||||
> **Nu ești sigur că acesta e directorul potrivit?**
|
||||
> Vezi [`../docs/instalare-si-migrare-oracle.md`](../docs/instalare-si-migrare-oracle.md) —
|
||||
> compară acest director cu `migration/` și `new-roa-oracle-server/` și conține arborele
|
||||
> de decizie.
|
||||
|
||||
> **Status testare ediții Oracle 21c:**
|
||||
>
|
||||
> | Ediție | Status | Mediu validat |
|
||||
@@ -17,7 +22,7 @@ Scripts and documentation for setting up ROA Oracle Database on Windows servers:
|
||||
| Scenario | Description |
|
||||
|----------|-------------|
|
||||
| **New Server** | Oracle 21c SE (non-CDB) or XE (CDB/PDB) + CONTAFIN_ORACLE.dmp |
|
||||
| **Migration** | Import existing DMP files (CONTAFIN_ORACLE + 30-50 companies) |
|
||||
| **Migration** | Import existing DMP files (CONTAFIN_ORACLE + 30-50 companies), inclusiv de pe Oracle XE 11 / 10g |
|
||||
| **Add Company** | Add new company schema to existing server |
|
||||
|
||||
---
|
||||
@@ -92,7 +97,7 @@ roa-windows-setup/
|
||||
│ ├── 01-setup-database.ps1 # Tablespace, profile, CONTAFIN_ORACLE user
|
||||
│ ├── 02-create-sys-objects.ps1# SYS objects (AUTH_PACK, NEWSCHEMA, etc.)
|
||||
│ ├── 03-import-contafin.ps1 # Import CONTAFIN_ORACLE schema
|
||||
│ ├── 04-create-synonyms-grants.ps1 # Public synonyms and grants
|
||||
│ ├── 04-create-synonyms-grants.ps1 # Public synonyms, grants + sys-grants.sql
|
||||
│ ├── 05-import-companies.ps1 # Batch import company schemas
|
||||
│ ├── 06-add-company.ps1 # Add new company to existing server
|
||||
│ ├── 07-verify-installation.ps1# Verify installation completeness
|
||||
@@ -134,7 +139,7 @@ roa-windows-setup/
|
||||
| `01-setup-database.ps1` | Create tablespace ROA, configure profile, create CONTAFIN_ORACLE user | Yes |
|
||||
| `02-create-sys-objects.ps1` | Install SYS objects: AUTH_PACK, NEWSCHEMA, EXECUTESCRIPTOS, UTL_MAIL | Yes |
|
||||
| `03-import-contafin.ps1` | Import CONTAFIN_ORACLE schema from DMP | Yes |
|
||||
| `04-create-synonyms-grants.ps1` | Create public synonyms and grants for CONTAFIN_ORACLE | Yes |
|
||||
| `04-create-synonyms-grants.ps1` | Public synonyms + grants for CONTAFIN_ORACLE, then `sys-grants.sql` (SYS grants, SYS synonyms, DMPDIR, data dictionary reads for `PACK_DIAG_SPATIU`) | Yes |
|
||||
| `05-import-companies.ps1` | Batch import company schemas from DMP files | Yes |
|
||||
| `06-add-company.ps1` | Add new company to existing server | Optional |
|
||||
| `07-verify-installation.ps1` | Verify installation completeness (objects, grants, synonyms) | Yes |
|
||||
@@ -311,19 +316,84 @@ Copy-Item \\server\dmp\NEWCOMPANY.dmp C:\DMPDIR\
|
||||
.\06-add-company.ps1 -CompanyName "NEWCOMPANY" -Password "ROMFASTSOFT"
|
||||
```
|
||||
|
||||
### Migration from Oracle 10g
|
||||
### Migrare de la un server client existent (Oracle XE 11 / 10g)
|
||||
|
||||
Exportul de pe sursă **nu** e automatizat aici — scripturile presupun DMP-urile deja în
|
||||
`C:\DMPDIR\` pe serverul nou.
|
||||
|
||||
**Sursa Oracle XE 11.2.** `impdp` din 21c acceptă direct seturile Data Pump produse de 11.2,
|
||||
deci fără `VERSION=`:
|
||||
|
||||
```bat
|
||||
REM pe serverul sursă, ca SYSTEM
|
||||
sqlplus system/parola@XE
|
||||
CREATE OR REPLACE DIRECTORY DMPDIR AS 'C:\DMPDIR';
|
||||
GRANT READ, WRITE ON DIRECTORY DMPDIR TO SYSTEM;
|
||||
|
||||
expdp system/parola@XE SCHEMAS=CONTAFIN_ORACLE DIRECTORY=DMPDIR ^
|
||||
DUMPFILE=contafin_oracle.dmp LOGFILE=export_contafin.log
|
||||
|
||||
expdp system/parola@XE SCHEMAS=FIRMA1,FIRMA2 DIRECTORY=DMPDIR ^
|
||||
DUMPFILE=firme_%U.dmp LOGFILE=export_firme.log PARALLEL=2
|
||||
REM ^ %U e substituția Data Pump; din interiorul unui fișier .bat se scrie %%U
|
||||
```
|
||||
|
||||
Lista schemelor se ia din `CONTAFIN_ORACLE.NOM_FIRME` (`WHERE sters = 0`) — aceeași listă pe
|
||||
care `07-verify-installation.ps1` o compară apoi cu schemele existente.
|
||||
|
||||
**Sursa Oracle 10g cu `exp` clasic.** Formatele `exp`/`expdp` nu sunt interschimbabile: un
|
||||
fișier produs cu `exp` se importă cu `imp`, nu cu `impdp`.
|
||||
|
||||
```powershell
|
||||
# 1. Export from Oracle 10g (on source Windows server)
|
||||
# 1. Export de pe sursă (exp clasic)
|
||||
exp system/password@ORCL file=C:\backup\COMPANY.dmp owner=COMPANY
|
||||
|
||||
# 2. Convert with Oracle 21c imp (if needed)
|
||||
# Or use impdp with VERSION parameter
|
||||
|
||||
# 3. Import using scripts
|
||||
.\05-import-companies.ps1 -DmpFile "COMPANY.dmp"
|
||||
# 2. Import
|
||||
imp system/password@XEPDB1 file=C:\DMPDIR\COMPANY.dmp fromuser=COMPANY touser=COMPANY
|
||||
```
|
||||
|
||||
**Înainte de a porni:** verifică plafonul XE (12 GB date de utilizator pe 21c XE, față de
|
||||
11 GB pe 11.2 XE):
|
||||
|
||||
```sql
|
||||
SELECT ROUND(SUM(bytes)/1024/1024/1024, 2) AS gb
|
||||
FROM dba_segments
|
||||
WHERE owner NOT IN ('SYS','SYSTEM','OUTLN','DBSNMP','XDB','APEX_040000');
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
### Scripturile `sys_*` la o migrare — capcana tabelei de versiuni
|
||||
|
||||
Obiectele deținute de **SYS nu călătoresc în DMP-ul de schemă**. În schimb, tabela de versiuni
|
||||
a lui `PACK_MIGRARE` trăiește în `CONTAFIN_ORACLE` și **vine cu DMP-ul** — iar scripturile
|
||||
`sys_*` își înregistrează acolo aplicarea (`pack_migrare.UpdateVersiune(..., 'SYS')`).
|
||||
|
||||
Consecința: pe baza nouă, `ROAACTUALIZARI` vede scripturile `sys_*` drept deja aplicate și le
|
||||
sare, deși în `SYS` nu există nimic. De aceea obiectele și granturile SYS se pun **la
|
||||
instalare**, prin `02-create-sys-objects.ps1` și `04-create-synonyms-grants.ps1`, și nu se
|
||||
așteaptă de la actualizator.
|
||||
|
||||
Ce e consolidat unde:
|
||||
|
||||
| Script sursă (`D:\roa\database\SCRIPTURI_CLAR\`) | Unde e aici |
|
||||
|---|---|
|
||||
| `sys_2026_01_14_01_AUTH_PACK` | `sql/sys-objects.sql` |
|
||||
| `sys_2026_08_08_02_SYS_INFO_TABLESPACE_PURJARE` | `sql/sys-objects.sql` + `sql/scheduler-jobs.sql` |
|
||||
| `sys_2026_08_03_05_DIAG_SPATIU_GRANT` | `sql/sys-grants.sql`, secțiunea `[5/5]` |
|
||||
| `sys_2026_08_03_07_DIAG_SPATIU_GRANT2` | `sql/sys-grants.sql`, secțiunea `[5/5]` |
|
||||
| `sys_2026_08_06_07_DIAG_SPATIU_GRANT3` | `sql/sys-grants.sql`, secțiunea `[5/5]` |
|
||||
|
||||
Secțiunea `[5/5]` acordă `SELECT` **direct** pe 18 vederi de dicționar către
|
||||
`CONTAFIN_ORACLE`. Grantul prin rolul `DBA` nu ajunge: rolurile nu se aplică în pachetele cu
|
||||
drepturi de definitor, iar `CONTAFIN_ORACLE.PACK_DIAG_SPATIU` este exact așa. Fără ele
|
||||
pachetul rămâne `INVALID` și jobul `DIAGSPATIU_ZILNIC` nu rulează.
|
||||
`07-verify-installation.ps1` raportează care dintre cele 18 lipsesc.
|
||||
|
||||
Un `sys_*` nou fie se consolidează în `sys-objects.sql` / `sys-grants.sql` /
|
||||
`scheduler-jobs.sql`, fie se pune în [`sql/sys-updates/`](sql/sys-updates/README.md) ca patch
|
||||
post-instalare.
|
||||
|
||||
---
|
||||
|
||||
## Uninstall / Cleanup
|
||||
|
||||
@@ -1,221 +1,286 @@
|
||||
#Requires -Version 5.1
|
||||
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Create public synonyms and grants for ROA Oracle.
|
||||
|
||||
.DESCRIPTION
|
||||
Creates public synonyms for CONTAFIN_ORACLE objects and configures:
|
||||
- Public synonyms for tables, views, packages, types (via synonyms-public.sql)
|
||||
- Public grants (SELECT, EXECUTE, REFERENCES) (via grants-public.sql)
|
||||
- SESIUNE context
|
||||
- Network ACL for CONTAFIN_ORACLE
|
||||
|
||||
.PARAMETER OracleHome
|
||||
Oracle home directory. If not specified, auto-detects.
|
||||
|
||||
.PARAMETER ServiceName
|
||||
Database service name. Default: XEPDB1
|
||||
|
||||
.PARAMETER SystemPassword
|
||||
SYSTEM user password. Default: romfastsoft
|
||||
|
||||
.PARAMETER SqlScriptsDir
|
||||
Directory containing SQL scripts. Default: ..\sql
|
||||
|
||||
.EXAMPLE
|
||||
.\04-create-synonyms-grants.ps1
|
||||
|
||||
.EXAMPLE
|
||||
.\04-create-synonyms-grants.ps1 -ServiceName "ROA" -SystemPassword "mypassword"
|
||||
|
||||
.NOTES
|
||||
File Name : 04-create-synonyms-grants.ps1
|
||||
Prerequisite : Run 03-import-contafin.ps1 first
|
||||
Copyright 2024 : ROMFAST
|
||||
#>
|
||||
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory = $false)]
|
||||
[string]$OracleHome,
|
||||
|
||||
[Parameter(Mandatory = $false)]
|
||||
[string]$ServiceName = "XEPDB1",
|
||||
|
||||
[Parameter(Mandatory = $false)]
|
||||
[string]$SystemPassword = "romfastsoft",
|
||||
|
||||
[Parameter(Mandatory = $false)]
|
||||
[string]$SqlScriptsDir
|
||||
)
|
||||
|
||||
$ErrorActionPreference = 'Stop'
|
||||
|
||||
# Source library functions
|
||||
. "$PSScriptRoot\lib\logging-functions.ps1"
|
||||
. "$PSScriptRoot\lib\oracle-functions.ps1"
|
||||
|
||||
# Initialize logging
|
||||
$logPath = Join-Path $PSScriptRoot "..\logs\04-create-synonyms-grants_$(Get-Date -Format 'yyyyMMdd_HHmmss').log"
|
||||
Initialize-LogFile -LogPath $logPath -ScriptName "04-create-synonyms-grants.ps1"
|
||||
|
||||
try {
|
||||
Write-LogSection "Creating Public Synonyms and Grants"
|
||||
|
||||
# Validate Oracle installation
|
||||
$oraHome = Get-OracleHome -OracleHome $OracleHome
|
||||
Write-LogSuccess "Oracle Home: $oraHome"
|
||||
|
||||
# Determine SQL scripts directory
|
||||
if (-not $SqlScriptsDir) {
|
||||
$SqlScriptsDir = Join-Path $PSScriptRoot "..\sql"
|
||||
}
|
||||
|
||||
# Verify SQL files exist
|
||||
$synonymsScript = Join-Path $SqlScriptsDir "synonyms-public.sql"
|
||||
$grantsScript = Join-Path $SqlScriptsDir "grants-public.sql"
|
||||
|
||||
if (-not (Test-Path -Path $synonymsScript)) {
|
||||
throw "synonyms-public.sql not found at $synonymsScript"
|
||||
}
|
||||
if (-not (Test-Path -Path $grantsScript)) {
|
||||
throw "grants-public.sql not found at $grantsScript"
|
||||
}
|
||||
|
||||
Write-Log "SQL scripts directory: $SqlScriptsDir"
|
||||
|
||||
# Test connection
|
||||
Write-Log "Testing database connection..."
|
||||
if (-not (Test-OracleConnection -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Password $SystemPassword)) {
|
||||
throw "Cannot connect to database. Please verify ServiceName and SystemPassword."
|
||||
}
|
||||
Write-LogSuccess "Database connection successful"
|
||||
|
||||
# Verify CONTAFIN_ORACLE exists and has objects
|
||||
Write-Log "Verifying CONTAFIN_ORACLE schema..."
|
||||
$counts = Get-SchemaObjectCount -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Password $SystemPassword -SchemaName "CONTAFIN_ORACLE"
|
||||
|
||||
$totalObjects = if ($counts['TOTAL']) { $counts['TOTAL'] } else { 0 }
|
||||
if ($totalObjects -eq 0) {
|
||||
throw "CONTAFIN_ORACLE schema has no objects. Run 03-import-contafin.ps1 first."
|
||||
}
|
||||
Write-LogSuccess "CONTAFIN_ORACLE has $totalObjects objects"
|
||||
|
||||
# =========================================================================
|
||||
# STEP 1: Create Public Synonyms (using synonyms-public.sql)
|
||||
# =========================================================================
|
||||
Write-LogSection "Creating Public Synonyms"
|
||||
Write-Log "Running synonyms-public.sql..."
|
||||
|
||||
$result = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYS" -Password $SystemPassword -SqlFile $synonymsScript -AsSysdba
|
||||
|
||||
if ($result -match "synonym_count|SYNONYM_NAME") {
|
||||
Write-LogSuccess "Public synonyms created successfully"
|
||||
}
|
||||
else {
|
||||
Write-LogWarning "Could not verify synonym creation"
|
||||
Write-LogDebug $result
|
||||
}
|
||||
|
||||
# =========================================================================
|
||||
# STEP 2: Create Grants and ACL (using grants-public.sql)
|
||||
# =========================================================================
|
||||
Write-LogSection "Creating Grants and Network ACL"
|
||||
Write-Log "Running grants-public.sql..."
|
||||
|
||||
$grantsResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYS" -Password $SystemPassword -SqlFile $grantsScript -AsSysdba
|
||||
|
||||
if ($grantsResult -match "Grant|ACL|Grants Complete") {
|
||||
Write-LogSuccess "Grants and ACL configured successfully"
|
||||
}
|
||||
else {
|
||||
Write-LogWarning "Could not verify grants configuration"
|
||||
Write-LogDebug $grantsResult
|
||||
}
|
||||
|
||||
# =========================================================================
|
||||
# STEP 3: Verify Results
|
||||
# =========================================================================
|
||||
Write-LogSection "Verifying Configuration"
|
||||
|
||||
# Count synonyms
|
||||
$countSql = @"
|
||||
SET PAGESIZE 0 FEEDBACK OFF VERIFY OFF HEADING OFF ECHO OFF
|
||||
SELECT 'SYNONYM_COUNT:' || COUNT(*)
|
||||
FROM dba_synonyms
|
||||
WHERE owner = 'PUBLIC'
|
||||
AND table_owner = 'CONTAFIN_ORACLE';
|
||||
EXIT;
|
||||
"@
|
||||
|
||||
$countResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYSTEM" -Password $SystemPassword -SqlCommand $countSql -Silent
|
||||
|
||||
$synonymCount = 0
|
||||
if ($countResult -match "SYNONYM_COUNT:(\d+)") {
|
||||
$synonymCount = [int]$Matches[1]
|
||||
}
|
||||
|
||||
Write-Log "Public synonyms for CONTAFIN_ORACLE: $synonymCount"
|
||||
|
||||
# Verify SESIUNE context exists (created by grants-public.sql or synonyms-public.sql)
|
||||
$contextSql = @"
|
||||
SET PAGESIZE 0 FEEDBACK OFF VERIFY OFF HEADING OFF ECHO OFF
|
||||
SELECT 'CONTEXT_EXISTS:' || COUNT(*)
|
||||
FROM dba_context
|
||||
WHERE namespace = 'SESIUNE';
|
||||
EXIT;
|
||||
"@
|
||||
|
||||
$contextResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYSTEM" -Password $SystemPassword -SqlCommand $contextSql -Silent
|
||||
|
||||
$contextExists = $false
|
||||
if ($contextResult -match "CONTEXT_EXISTS:(\d+)") {
|
||||
$contextExists = [int]$Matches[1] -gt 0
|
||||
}
|
||||
|
||||
if ($contextExists) {
|
||||
Write-LogSuccess "SESIUNE context exists"
|
||||
}
|
||||
else {
|
||||
Write-LogWarning "SESIUNE context not found - creating..."
|
||||
$createContextSql = @"
|
||||
CREATE CONTEXT SESIUNE USING CONTAFIN_ORACLE.SET_VARIABILE;
|
||||
EXIT;
|
||||
"@
|
||||
Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYS" -Password $SystemPassword -SqlCommand $createContextSql -AsSysdba
|
||||
}
|
||||
|
||||
# =========================================================================
|
||||
# Summary
|
||||
# =========================================================================
|
||||
Write-LogSection "Setup Complete"
|
||||
Write-LogSuccess "Public synonyms and grants configured!"
|
||||
Write-Log ""
|
||||
Write-Log "Summary:"
|
||||
Write-Log " SQL scripts used:"
|
||||
Write-Log " - synonyms-public.sql (all public synonyms)"
|
||||
Write-Log " - grants-public.sql (all grants and ACL)"
|
||||
Write-Log " Public synonyms created: $synonymCount"
|
||||
Write-Log " SESIUNE context: $(if ($contextExists) { 'Verified' } else { 'Created' })"
|
||||
Write-Log " Network ACL: Configured (roaupdate.xml)"
|
||||
Write-Log ""
|
||||
Write-Log "Next steps:"
|
||||
Write-Log " 1. Run 05-import-companies.ps1 to import company schemas"
|
||||
|
||||
Close-LogFile -Success $true
|
||||
exit 0
|
||||
}
|
||||
catch {
|
||||
Write-LogError "Setup failed: $_"
|
||||
Write-LogError $_.ScriptStackTrace
|
||||
Close-LogFile -Success $false
|
||||
exit 1
|
||||
}
|
||||
#Requires -Version 5.1
|
||||
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Create public synonyms and grants for ROA Oracle.
|
||||
|
||||
.DESCRIPTION
|
||||
Creates public synonyms for CONTAFIN_ORACLE objects and configures:
|
||||
- Public synonyms for tables, views, packages, types (via synonyms-public.sql)
|
||||
- Public grants (SELECT, EXECUTE, REFERENCES) (via grants-public.sql)
|
||||
- SYS grants, SYS public synonyms, DMPDIR and data dictionary reads
|
||||
required by PACK_DIAG_SPATIU (via sys-grants.sql)
|
||||
- SESIUNE context
|
||||
- Network ACL for CONTAFIN_ORACLE
|
||||
|
||||
.PARAMETER OracleHome
|
||||
Oracle home directory. If not specified, auto-detects.
|
||||
|
||||
.PARAMETER ServiceName
|
||||
Database service name. Default: XEPDB1
|
||||
|
||||
.PARAMETER SystemPassword
|
||||
SYSTEM user password. Default: romfastsoft
|
||||
|
||||
.PARAMETER SqlScriptsDir
|
||||
Directory containing SQL scripts. Default: ..\sql
|
||||
|
||||
.EXAMPLE
|
||||
.\04-create-synonyms-grants.ps1
|
||||
|
||||
.EXAMPLE
|
||||
.\04-create-synonyms-grants.ps1 -ServiceName "ROA" -SystemPassword "mypassword"
|
||||
|
||||
.NOTES
|
||||
File Name : 04-create-synonyms-grants.ps1
|
||||
Prerequisite : Run 03-import-contafin.ps1 first
|
||||
Copyright 2024 : ROMFAST
|
||||
#>
|
||||
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory = $false)]
|
||||
[string]$OracleHome,
|
||||
|
||||
[Parameter(Mandatory = $false)]
|
||||
[string]$ServiceName = "XEPDB1",
|
||||
|
||||
[Parameter(Mandatory = $false)]
|
||||
[string]$SystemPassword = "romfastsoft",
|
||||
|
||||
[Parameter(Mandatory = $false)]
|
||||
[string]$SqlScriptsDir
|
||||
)
|
||||
|
||||
$ErrorActionPreference = 'Stop'
|
||||
|
||||
# Source library functions
|
||||
. "$PSScriptRoot\lib\logging-functions.ps1"
|
||||
. "$PSScriptRoot\lib\oracle-functions.ps1"
|
||||
|
||||
# Initialize logging
|
||||
$logPath = Join-Path $PSScriptRoot "..\logs\04-create-synonyms-grants_$(Get-Date -Format 'yyyyMMdd_HHmmss').log"
|
||||
Initialize-LogFile -LogPath $logPath -ScriptName "04-create-synonyms-grants.ps1"
|
||||
|
||||
try {
|
||||
Write-LogSection "Creating Public Synonyms and Grants"
|
||||
|
||||
# Validate Oracle installation
|
||||
$oraHome = Get-OracleHome -OracleHome $OracleHome
|
||||
Write-LogSuccess "Oracle Home: $oraHome"
|
||||
|
||||
# Determine SQL scripts directory
|
||||
if (-not $SqlScriptsDir) {
|
||||
$SqlScriptsDir = Join-Path $PSScriptRoot "..\sql"
|
||||
}
|
||||
|
||||
# Verify SQL files exist
|
||||
$synonymsScript = Join-Path $SqlScriptsDir "synonyms-public.sql"
|
||||
$grantsScript = Join-Path $SqlScriptsDir "grants-public.sql"
|
||||
$sysGrantsScript = Join-Path $SqlScriptsDir "sys-grants.sql"
|
||||
|
||||
if (-not (Test-Path -Path $synonymsScript)) {
|
||||
throw "synonyms-public.sql not found at $synonymsScript"
|
||||
}
|
||||
if (-not (Test-Path -Path $grantsScript)) {
|
||||
throw "grants-public.sql not found at $grantsScript"
|
||||
}
|
||||
if (-not (Test-Path -Path $sysGrantsScript)) {
|
||||
throw "sys-grants.sql not found at $sysGrantsScript"
|
||||
}
|
||||
|
||||
Write-Log "SQL scripts directory: $SqlScriptsDir"
|
||||
|
||||
# Test connection
|
||||
Write-Log "Testing database connection..."
|
||||
if (-not (Test-OracleConnection -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Password $SystemPassword)) {
|
||||
throw "Cannot connect to database. Please verify ServiceName and SystemPassword."
|
||||
}
|
||||
Write-LogSuccess "Database connection successful"
|
||||
|
||||
# Verify CONTAFIN_ORACLE exists and has objects
|
||||
Write-Log "Verifying CONTAFIN_ORACLE schema..."
|
||||
$counts = Get-SchemaObjectCount -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Password $SystemPassword -SchemaName "CONTAFIN_ORACLE"
|
||||
|
||||
$totalObjects = if ($counts['TOTAL']) { $counts['TOTAL'] } else { 0 }
|
||||
if ($totalObjects -eq 0) {
|
||||
throw "CONTAFIN_ORACLE schema has no objects. Run 03-import-contafin.ps1 first."
|
||||
}
|
||||
Write-LogSuccess "CONTAFIN_ORACLE has $totalObjects objects"
|
||||
|
||||
# =========================================================================
|
||||
# STEP 1: Create Public Synonyms (using synonyms-public.sql)
|
||||
# =========================================================================
|
||||
Write-LogSection "Creating Public Synonyms"
|
||||
Write-Log "Running synonyms-public.sql..."
|
||||
|
||||
$result = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYS" -Password $SystemPassword -SqlFile $synonymsScript -AsSysdba
|
||||
|
||||
if ($result -match "synonym_count|SYNONYM_NAME") {
|
||||
Write-LogSuccess "Public synonyms created successfully"
|
||||
}
|
||||
else {
|
||||
Write-LogWarning "Could not verify synonym creation"
|
||||
Write-LogDebug $result
|
||||
}
|
||||
|
||||
# =========================================================================
|
||||
# STEP 2: Create Grants and ACL (using grants-public.sql)
|
||||
# =========================================================================
|
||||
Write-LogSection "Creating Grants and Network ACL"
|
||||
Write-Log "Running grants-public.sql..."
|
||||
|
||||
$grantsResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYS" -Password $SystemPassword -SqlFile $grantsScript -AsSysdba
|
||||
|
||||
if ($grantsResult -match "Grant|ACL|Grants Complete") {
|
||||
Write-LogSuccess "Grants and ACL configured successfully"
|
||||
}
|
||||
else {
|
||||
Write-LogWarning "Could not verify grants configuration"
|
||||
Write-LogDebug $grantsResult
|
||||
}
|
||||
|
||||
# =========================================================================
|
||||
# STEP 3: SYS Grants, SYS Synonyms and Dictionary Reads (sys-grants.sql)
|
||||
# =========================================================================
|
||||
# Ruleaza dupa import: tabela de versiuni a lui PACK_MIGRARE traieste in
|
||||
# CONTAFIN_ORACLE si vine cu DMP-ul, marcand scripturile sys_* drept aplicate.
|
||||
# ROAACTUALIZARI nu le mai ruleaza pe baza noua, deci granturile catre SYS
|
||||
# trebuie puse aici, la instalare.
|
||||
Write-LogSection "Creating SYS Grants and Dictionary Reads"
|
||||
Write-Log "Running sys-grants.sql..."
|
||||
|
||||
$sysGrantsResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYS" -Password $SystemPassword -SqlFile $sysGrantsScript -AsSysdba
|
||||
|
||||
if ($sysGrantsResult -match "SYS Grants and Synonyms Installation Complete") {
|
||||
Write-LogSuccess "SYS grants, synonyms and dictionary reads configured"
|
||||
}
|
||||
else {
|
||||
Write-LogWarning "Could not verify sys-grants.sql execution"
|
||||
Write-LogDebug $sysGrantsResult
|
||||
}
|
||||
|
||||
# =========================================================================
|
||||
# STEP 4: Verify Results
|
||||
# =========================================================================
|
||||
Write-LogSection "Verifying Configuration"
|
||||
|
||||
# Count synonyms
|
||||
$countSql = @"
|
||||
SET PAGESIZE 0 FEEDBACK OFF VERIFY OFF HEADING OFF ECHO OFF
|
||||
SELECT 'SYNONYM_COUNT:' || COUNT(*)
|
||||
FROM dba_synonyms
|
||||
WHERE owner = 'PUBLIC'
|
||||
AND table_owner = 'CONTAFIN_ORACLE';
|
||||
EXIT;
|
||||
"@
|
||||
|
||||
$countResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYSTEM" -Password $SystemPassword -SqlCommand $countSql -Silent
|
||||
|
||||
$synonymCount = 0
|
||||
if ($countResult -match "SYNONYM_COUNT:(\d+)") {
|
||||
$synonymCount = [int]$Matches[1]
|
||||
}
|
||||
|
||||
Write-Log "Public synonyms for CONTAFIN_ORACLE: $synonymCount"
|
||||
|
||||
# Verify SESIUNE context exists (created by grants-public.sql or synonyms-public.sql)
|
||||
$contextSql = @"
|
||||
SET PAGESIZE 0 FEEDBACK OFF VERIFY OFF HEADING OFF ECHO OFF
|
||||
SELECT 'CONTEXT_EXISTS:' || COUNT(*)
|
||||
FROM dba_context
|
||||
WHERE namespace = 'SESIUNE';
|
||||
EXIT;
|
||||
"@
|
||||
|
||||
$contextResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYSTEM" -Password $SystemPassword -SqlCommand $contextSql -Silent
|
||||
|
||||
$contextExists = $false
|
||||
if ($contextResult -match "CONTEXT_EXISTS:(\d+)") {
|
||||
$contextExists = [int]$Matches[1] -gt 0
|
||||
}
|
||||
|
||||
if ($contextExists) {
|
||||
Write-LogSuccess "SESIUNE context exists"
|
||||
}
|
||||
else {
|
||||
Write-LogWarning "SESIUNE context not found - creating..."
|
||||
$createContextSql = @"
|
||||
CREATE CONTEXT SESIUNE USING CONTAFIN_ORACLE.SET_VARIABILE;
|
||||
EXIT;
|
||||
"@
|
||||
Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYS" -Password $SystemPassword -SqlCommand $createContextSql -AsSysdba
|
||||
}
|
||||
|
||||
# Granturile de dictionar cerute de PACK_DIAG_SPATIU (sys-grants.sql [5/5])
|
||||
$dictSql = @"
|
||||
SET PAGESIZE 0 FEEDBACK OFF VERIFY OFF HEADING OFF ECHO OFF
|
||||
SELECT 'DICT_GRANTS:' || COUNT(*)
|
||||
FROM dba_tab_privs
|
||||
WHERE grantee = 'CONTAFIN_ORACLE'
|
||||
AND grantor = 'SYS'
|
||||
AND privilege = 'SELECT'
|
||||
AND table_name IN (
|
||||
'DBA_DATA_FILES', 'DBA_FREE_SPACE', 'DBA_TEMP_FILES', 'DBA_SEGMENTS',
|
||||
'DBA_TAB_STATS_HISTORY', 'DBA_SCHEDULER_JOB_RUN_DETAILS', 'DBA_RECYCLEBIN',
|
||||
'V_`$INSTANCE', 'V_`$DATABASE', 'V_`$PARAMETER', 'V_`$TRANSACTION',
|
||||
'V_`$TEMP_SPACE_HEADER', 'V_`$FLASH_RECOVERY_AREA_USAGE',
|
||||
'DBA_TABLESPACES', 'V_`$VERSION',
|
||||
'DBA_LOBS', 'DBA_LOB_PARTITIONS', 'DBA_INDEXES'
|
||||
);
|
||||
EXIT;
|
||||
"@
|
||||
|
||||
$dictResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
|
||||
-Username "SYSTEM" -Password $SystemPassword -SqlCommand $dictSql -Silent
|
||||
|
||||
$dictGrants = 0
|
||||
if ($dictResult -match "DICT_GRANTS:(\d+)") {
|
||||
$dictGrants = [int]$Matches[1]
|
||||
}
|
||||
|
||||
if ($dictGrants -ge 15) {
|
||||
Write-LogSuccess "Dictionary grants for PACK_DIAG_SPATIU: $dictGrants / 18"
|
||||
}
|
||||
else {
|
||||
Write-LogWarning "Dictionary grants for PACK_DIAG_SPATIU: $dictGrants / 18 (asteptat minim 15)"
|
||||
Write-LogWarning "Fara ele PACK_DIAG_SPATIU ramane INVALID si DIAGSPATIU_ZILNIC nu ruleaza."
|
||||
Write-LogWarning "Verifica sectiunea [5/5] din sql\sys-grants.sql"
|
||||
}
|
||||
|
||||
# =========================================================================
|
||||
# Summary
|
||||
# =========================================================================
|
||||
Write-LogSection "Setup Complete"
|
||||
Write-LogSuccess "Public synonyms and grants configured!"
|
||||
Write-Log ""
|
||||
Write-Log "Summary:"
|
||||
Write-Log " SQL scripts used:"
|
||||
Write-Log " - synonyms-public.sql (all public synonyms)"
|
||||
Write-Log " - grants-public.sql (all grants and ACL)"
|
||||
Write-Log " - sys-grants.sql (SYS grants, SYS synonyms, DMPDIR, dictionary reads)"
|
||||
Write-Log " Public synonyms created: $synonymCount"
|
||||
Write-Log " SESIUNE context: $(if ($contextExists) { 'Verified' } else { 'Created' })"
|
||||
Write-Log " Network ACL: Configured (roaupdate.xml)"
|
||||
Write-Log " Dictionary grants: $dictGrants / 18 (PACK_DIAG_SPATIU)"
|
||||
Write-Log ""
|
||||
Write-Log "Next steps:"
|
||||
Write-Log " 1. Run 05-import-companies.ps1 to import company schemas"
|
||||
|
||||
Close-LogFile -Success $true
|
||||
exit 0
|
||||
}
|
||||
catch {
|
||||
Write-LogError "Setup failed: $_"
|
||||
Write-LogError $_.ScriptStackTrace
|
||||
Close-LogFile -Success $false
|
||||
exit 1
|
||||
}
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -24,7 +24,7 @@ PROMPT
|
||||
-- SECTION 1: GRANTS TO CONTAFIN_ORACLE
|
||||
-- ============================================================================
|
||||
PROMPT
|
||||
PROMPT [1/4] Granting privileges to CONTAFIN_ORACLE...
|
||||
PROMPT [1/5] Granting privileges to CONTAFIN_ORACLE...
|
||||
|
||||
-- Execute on SYS packages
|
||||
GRANT EXECUTE ON SYS.AUTH_PACK TO CONTAFIN_ORACLE;
|
||||
@@ -51,7 +51,7 @@ PROMPT Grants to CONTAFIN_ORACLE complete.
|
||||
-- SECTION 2: PUBLIC GRANTS
|
||||
-- ============================================================================
|
||||
PROMPT
|
||||
PROMPT [2/4] Granting public privileges...
|
||||
PROMPT [2/5] Granting public privileges...
|
||||
|
||||
-- UTL packages for public use
|
||||
GRANT EXECUTE ON SYS.UTL_FILE TO PUBLIC;
|
||||
@@ -62,7 +62,7 @@ PROMPT Public grants complete.
|
||||
-- SECTION 3: SYS PUBLIC SYNONYMS
|
||||
-- ============================================================================
|
||||
PROMPT
|
||||
PROMPT [3/4] Creating SYS public synonyms...
|
||||
PROMPT [3/5] Creating SYS public synonyms...
|
||||
|
||||
-- Synonyms for SYS procedures
|
||||
BEGIN EXECUTE IMMEDIATE 'DROP PUBLIC SYNONYM SYN_NEWSCHEMA'; EXCEPTION WHEN OTHERS THEN NULL; END;
|
||||
@@ -91,7 +91,7 @@ PROMPT SYS public synonyms complete.
|
||||
-- SECTION 4: DIRECTORY DMPDIR
|
||||
-- ============================================================================
|
||||
PROMPT
|
||||
PROMPT [4/4] Creating DMPDIR directory...
|
||||
PROMPT [4/5] Creating DMPDIR directory...
|
||||
|
||||
BEGIN
|
||||
EXECUTE IMMEDIATE 'CREATE OR REPLACE DIRECTORY DMPDIR AS ''C:\DMPDIR''';
|
||||
@@ -104,6 +104,72 @@ END;
|
||||
|
||||
GRANT READ, WRITE ON DIRECTORY DMPDIR TO PUBLIC;
|
||||
|
||||
-- ============================================================================
|
||||
-- SECTION 5: GRANTURI DE DICTIONAR PENTRU PACK_DIAG_SPATIU
|
||||
-- ============================================================================
|
||||
-- Consolideaza scripturile de livrare din repo-ul COMUN:
|
||||
-- sys_2026_08_03_05_DIAG_SPATIU_GRANT - diagnosticul de baza
|
||||
-- sys_2026_08_03_07_DIAG_SPATIU_GRANT2 - sectiunea XE (plafon editie)
|
||||
-- sys_2026_08_06_07_DIAG_SPATIU_GRANT3 - provenienta segmentelor LOB/index
|
||||
--
|
||||
-- CONTAFIN_ORACLE.PACK_DIAG_SPATIU are drepturi de definitor, iar rolul DBA NU se
|
||||
-- aplica in pachetele cu drepturi de definitor. Referintele statice la dba_*/v$*
|
||||
-- au nevoie de grant DIRECT catre user, altfel pachetul ramane INVALID si jobul
|
||||
-- DIAGSPATIU_ZILNIC nu ruleaza.
|
||||
--
|
||||
-- ATENTIE la migrarea unui client existent: tabela de versiuni a lui PACK_MIGRARE
|
||||
-- traieste in CONTAFIN_ORACLE si vine cu DMP-ul. Baza noua va raporta scripturile
|
||||
-- sys_* de mai sus drept "deja aplicate", iar ROAACTUALIZARI le va sari - desi in
|
||||
-- SYS nu exista nimic. De aceea granturile se aplica de aici, la instalare, nu
|
||||
-- prin actualizator.
|
||||
--
|
||||
-- Vederile absente pe versiunea/editia curenta sunt ignorate (ORA-00942).
|
||||
-- ============================================================================
|
||||
PROMPT
|
||||
PROMPT [5/5] Granting data dictionary reads to CONTAFIN_ORACLE (PACK_DIAG_SPATIU)...
|
||||
|
||||
DECLARE
|
||||
TYPE t_lista IS TABLE OF VARCHAR2(30);
|
||||
laObiecte t_lista := t_lista(
|
||||
-- sys_2026_08_03_05_DIAG_SPATIU_GRANT
|
||||
'DBA_DATA_FILES', 'DBA_FREE_SPACE', 'DBA_TEMP_FILES',
|
||||
'DBA_SEGMENTS', 'DBA_TAB_STATS_HISTORY',
|
||||
'DBA_SCHEDULER_JOB_RUN_DETAILS', 'DBA_RECYCLEBIN',
|
||||
'V_$INSTANCE', 'V_$DATABASE', 'V_$PARAMETER', 'V_$TRANSACTION',
|
||||
'V_$TEMP_SPACE_HEADER', 'V_$FLASH_RECOVERY_AREA_USAGE',
|
||||
-- sys_2026_08_03_07_DIAG_SPATIU_GRANT2
|
||||
'DBA_TABLESPACES', 'V_$VERSION',
|
||||
-- sys_2026_08_06_07_DIAG_SPATIU_GRANT3
|
||||
'DBA_LOBS', 'DBA_LOB_PARTITIONS', 'DBA_INDEXES'
|
||||
);
|
||||
lnAcordate PLS_INTEGER := 0;
|
||||
lnSarite PLS_INTEGER := 0;
|
||||
BEGIN
|
||||
FOR i IN 1 .. laObiecte.COUNT LOOP
|
||||
BEGIN
|
||||
EXECUTE IMMEDIATE 'GRANT SELECT ON SYS.' || laObiecte(i) ||
|
||||
' TO CONTAFIN_ORACLE';
|
||||
lnAcordate := lnAcordate + 1;
|
||||
EXCEPTION
|
||||
WHEN OTHERS THEN
|
||||
IF SQLCODE = -942 THEN
|
||||
lnSarite := lnSarite + 1;
|
||||
DBMS_OUTPUT.PUT_LINE(' SKIP (absent pe aceasta versiune): ' ||
|
||||
laObiecte(i));
|
||||
ELSE
|
||||
RAISE;
|
||||
END IF;
|
||||
END;
|
||||
END LOOP;
|
||||
|
||||
DBMS_OUTPUT.PUT_LINE(' Granturi de dictionar acordate: ' || lnAcordate ||
|
||||
' / ' || laObiecte.COUNT ||
|
||||
' (sarite: ' || lnSarite || ')');
|
||||
END;
|
||||
/
|
||||
|
||||
PROMPT Dictionary grants complete.
|
||||
|
||||
PROMPT
|
||||
PROMPT ============================================================
|
||||
PROMPT SYS Grants and Synonyms Installation Complete
|
||||
|
||||
@@ -10,10 +10,21 @@ scripts (`sys_2006_*.sql` through `sys_2026_*.sql`) here.
|
||||
|
||||
**Initial setup order:**
|
||||
1. `sys-objects.sql` - Creates all SYS objects (tables, packages, procedures, views)
|
||||
— rulat de `scripts/02-create-sys-objects.ps1`
|
||||
2. Import `CONTAFIN_ORACLE.dmp` - Application schema
|
||||
3. `sys-grants.sql` - Grants and public synonyms
|
||||
— rulat de `scripts/03-import-contafin.ps1`
|
||||
3. `sys-grants.sql` - Grants, public synonyms, DMPDIR și granturile de dicționar cerute de
|
||||
`PACK_DIAG_SPATIU` (secțiunea `[5/5]`, consolidând `sys_2026_08_03_05`,
|
||||
`sys_2026_08_03_07` și `sys_2026_08_06_07`)
|
||||
— rulat de `scripts/04-create-synonyms-grants.ps1`, după import
|
||||
4. `sys-updates/*.sql` - (Optional) Post-install patches
|
||||
|
||||
> **Atenție la migrări.** Tabela de versiuni a lui `PACK_MIGRARE` trăiește în
|
||||
> `CONTAFIN_ORACLE` și vine cu DMP-ul, deci pe baza nouă `ROAACTUALIZARI` va considera
|
||||
> scripturile `sys_*` deja aplicate și le va sări — deși în `SYS` nu există nimic. Orice
|
||||
> `sys_*` necesar unei instalări curate trebuie consolidat în pașii 1-3 de mai sus, nu
|
||||
> lăsat pe seama actualizatorului.
|
||||
|
||||
## When to Use This Folder
|
||||
|
||||
Place scripts here when you need to:
|
||||
|
||||
Reference in New Issue
Block a user